3 ms·
Not sure this plausible. You'd need clarity to all the sourced parts and entire supply chain and logistical chain. Then complete oversight over the assembly and
by grumps 13y ago
Not sure this plausible. You'd need clarity to all the sourced parts and entire supply chain and logistical chain. Then complete oversight over the assembly and logistics. I'm guessing that backdoors are really inserted at the firmware level (in most cases) and therefore you'd need the ability to flash new firmware with valid signatures and checksums straight from the manufacturer but you'd probably want an independent audit of said firmware.
- ds9 13y agoI agree that there is a theoretical scenario that all the production line are trojaned, or that Lenovo is cooperating with the customer's adversary at assembly time. However, my question was intended for what is more likely the practical situation today: that only a subset of computers get the treatment, and that it is applied after the factory, as per the recently liberated information. Apparently I do need to look into the whole "verifying firmware" area. Maybe I'll try to compare checksums and other data with other owners of the same model and BIOS rev, on a suitable forum.
- grumps 13y agoI'd expect that if a trojan were to be inserted that it will probably want access to all interfaces. I would take extra care at your hardrive interface, USB interface and Ethernet interface. I'd look for JTAG connectors on the boards to see if direct flashing is plausible. I'd also look for damage done from removing them. Small point be social sourcing could generate a false positive unless you can verify said individuals interests. Of course removing anything placed by warrant is possibly illegal irregardless of you position on it. {this isn't legal advice} I'd also say this would take a significant amount of effort to validate and you're likely to find quasi poor information.